2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-23357 | MEDIUM | 4.8 | 0.3% | Dec 19, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-23356 | HIGH | 7.2 | 0.7% | Dec 19, 2024 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ... |
| CVE-2023-23354 | HIGH | 8.7 | 0.4% | Dec 19, 2024 | A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. If exploi... |
| CVE-2023-21586 | MEDIUM | 5.5 | 2.1% | Dec 19, 2024 | Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are ... |
| CVE-2023-50956 | MEDIUM | 4.9 | 0.3% | Dec 18, 2024 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive... |
| CVE-2023-34990 | CRITICAL | 9.8 | 24.9% | Dec 18, 2024 | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to ex... |
| CVE-2023-37940 | MEDIUM | 4.8 | 0.3% | Dec 17, 2024 | Cross-site scripting (XSS) vulnerability in the edit Service Access Policy page in Liferay Portal 7.0.0 through 7.4.3.87... |
| CVE-2023-29476 | CRITICAL | 9.1 | 0.4% | Dec 14, 2024 | In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malforme... |
| CVE-2023-44149 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in BeRocket Brands for WooCommerce brands-for-woocommerce allows Exploiting Incorrec... |
| CVE-2023-44147 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting... |
| CVE-2023-44142 | MEDIUM | 5.4 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Deepen Bajracharya Inactive Logout inactive-logout allows Exploiting Incorrectly ... |
| CVE-2023-41952 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Contact Form - WPManageNinja LLC FluentForm allows Exploiting Incorrectly Configu... |
| CVE-2023-41951 | MEDIUM | 4.3 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectl... |
| CVE-2023-41875 | CRITICAL | 9.8 | 0.6% | Dec 13, 2024 | Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Acce... |
| CVE-2023-41873 | MEDIUM | 4.3 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access... |
| CVE-2023-41870 | HIGH | 8.8 | 0.6% | Dec 13, 2024 | Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2023-41869 | MEDIUM | 4.3 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configure... |
| CVE-2023-41866 | MEDIUM | 4.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Team Plugins360 Automatic YouTube Gallery allows Exploiting Incorrectly Configure... |
| CVE-2023-41865 | MEDIUM | 4.3 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in bqworks Slider Pro allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2023-41862 | MEDIUM | 5.3 | 0.6% | Dec 13, 2024 | Weak Authentication vulnerability in Guido VS Contact Form allows Authentication Abuse.This issue affects VS Contact For... |
| CVE-2023-41857 | MEDIUM | 5.4 | 0.4% | Dec 13, 2024 | Missing Authorization vulnerability in ClickToTweet.com Click To Tweet allows Exploiting Incorrectly Configured Access C... |
| CVE-2023-41849 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in WP Happy Coders Posts Like Dislike allows Exploiting Incorrectly Configured Acces... |
| CVE-2023-41848 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Majeed Raza Carousel Slider allows Exploiting Incorrectly Configured Access Contr... |
| CVE-2023-41803 | MEDIUM | 5.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in BitPay BitPay Checkout for WooCommerce allows Exploiting Incorrectly Configured A... |
| CVE-2023-41802 | MEDIUM | 4.3 | 0.5% | Dec 13, 2024 | Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Con... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now